Description
In the Linux kernel, the following vulnerability has been resolved:

drm/amd/display: Fix dangling pointer in CRTC reset function

amdgpu_dm_crtc_reset_state() frees the old state before allocating
a new one. If kzalloc() fails, the function returns without updating
the state pointer, leaving a dangling pointer to already freed memory.

Fix this by allocating the new state first. On allocation failure, the
old state remains untouched and the function safely returns.

Found by Linux Verification Center (linuxtesting.org) with SVACE.

[adjust for movement around current amd-staging-drm-next]
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

The AMDGPU DRM driver contains a routine that frees the previous CRTC state before allocating a new one. When the allocation fails, the function returns early without updating the state pointer, leaving a dangling reference to already freed kernel memory. This creates a use‑after‑free condition that can corrupt kernel memory when the stale pointer is later accessed. The corruption may allow an attacker to overwrite critical kernel structures, potentially leading to control‑flow hijack or kernel panic. The likely attack vector is an entity that can trigger a memory allocation failure and subsequently cause the driver to use the dangling pointer, typically implying local privileged execution or an existing kernel exploitation chain. An attacker would need to exercise control over the display subsystem, which is usually limited to privileged users or compromised processes.

Affected Systems

All Linux kernel builds that include the AMDGPU DRM driver are affected. The vulnerability exists in the amdgpu_dm_crtc_reset_state routine prior to the patch; the security fix is present in later kernel releases but no specific version numbers are provided in the advisory. Systems running patched kernels are no longer susceptible.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity for kernel memory corruption. The EPSS score of less than 1% suggests that, at present, exploitation in the wild is unlikely. The vulnerability is not listed in CISA's KEV catalog. Because the flaw requires an allocation failure and a subsequent use of the stale pointer, the difficulty of exploitation is not trivial, but once achieved, the impact can be critical, providing a path to privilege escalation or denial of service.

Generated by OpenCVE AI on September 19, 2026 at 15:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a Linux kernel release that includes the AMDGPU DRM driver patch fixing the dangling pointer in the CRTC reset function.
  • Reboot the system so the updated driver is loaded and the fix is active.
  • If a kernel update is not immediately possible, disable the AMDGPU DRM driver by adding the boot parameter 'amdgpu.modeset=0' or by removing the module, preventing execution of the vulnerable code until a patch can be applied.

Generated by OpenCVE AI on September 19, 2026 at 15:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix dangling pointer in CRTC reset function amdgpu_dm_crtc_reset_state() frees the old state before allocating a new one. If kzalloc() fails, the function returns without updating the state pointer, leaving a dangling pointer to already freed memory. Fix this by allocating the new state first. On allocation failure, the old state remains untouched and the function safely returns. Found by Linux Verification Center (linuxtesting.org) with SVACE. [adjust for movement around current amd-staging-drm-next]
Title drm/amd/display: Fix dangling pointer in CRTC reset function
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:56:20.794Z

Reserved: 2026-09-17T16:02:15.090Z

Link: CVE-2026-93175

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:13.290

Modified: 2026-09-18T18:18:23.530

Link: CVE-2026-93175

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T05:45:16Z

Weaknesses